When planning to secure a SharePoint 2013 environment, you first need to consider the type of scenario you need to support as in the following:

Each of these scenarios have different security requirements and they also each require different security measures and technologies.

Defense in depth

Because the majority of organizations store confidential, regulated, or at the very least, sensitive information on their SharePoint sites, it makes sense that these organizations need to commit to a defense in depth approach when planning security for their SharePoint farm. The term defense in depth refers to the use of multilayered security measures to help protect the information resources or an organization. The term has been borrowed from the military principle that it is much harder to breach a defense that is complex and has several layers to it than it is to breach a single barrier. So, the defense in depth principle for SharePoint requires considering your security at multiple levels of your infrastructure.

These are some examples of areas you need to include in your security planning:

Secure Deployment SharePoint

Hardening a SharePoint Server

Typically, security hardening refers to the process of securing a system by reducing its surface of vulnerability, by removing or disabling unnecessary software. In a SharePoint server farm environment, individual servers play specific roles, such as web server, application server and database server. Security hardening measures for these servers depend on the role each server plays. The primary measure for server hardening is to shut down non-essential Windows and SharePoint services.

Web and application server service hardening

Services that use insecure protocols, or that run under accounts with too much privilege are security risks; therefore, if you do not need them, disable them. When you disable non-essential and unnecessary services, you rapidly reduce your attack surface and reduce your maintenance overhead.

It is also possible that services running in Windows can be exploited and used by malicious attackers to obtain access to your system and resources. You should disable all services that your servers and applications do not require. To help secure your web and application servers, you should shut down all non-essential services other than those in the following list. Ensure that the following services are enabled on your web and application servers:
You should ensure that the following services are enabled on the servers that host the corresponding roles: